Should be easy to block. Just block the cron-job.org domain.
As someone else mentioned that address is an obvious joe-job. And scoring it high doesn't help that much. It worked for the first few weeks, then they went to contact@<random string> to presumably get around that. I was surprised to see in the last few that they had gone back to the cron-job.org domain for the fake sender.
For some reason these are bypassing SA on my system, I suspect due to the size.
Loren